mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-28 15:41:57 +02:00
v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)
* fix(browse): prepare reliable cookie import wave for validation * ci: sequence quality and behavior for validation branch * fix(browse): isolate Windows qualification and preserve native diagnostics * test(browse): cover cookie workflow quality and isolate Windows user paths * test(browse): trace native member startup and initialize fresh folders * fix(browse): keep Windows member stdin alive through EOF * fix(browse): latch native timeouts and compare contained Edge startup * test(browse): verify native version metadata and actual Windows argv * test(browse): qualify Dia import on isolated macOS CI * fix(browse): require picker origin for session mutations * fix(browse): bound credential reads through stream completion * test(browse): inspect owned Windows process arguments natively * test(evals): preserve passing coverage during cookie repair reruns * test(browse): isolate Dia qualification in a fresh macOS account * test(browse): pass bounded integer timeouts to native Mac probes * test(browse): distinguish Windows profile initialization from containment * test(browse): await descendant pipe readiness before parent exit * test(browse): initialize and restore isolated macOS Keychain state * test(browse): initialize Windows fixture folders before qualification * test(ci): pin the same Node runtime across Windows checks * test(browse): distinguish native macOS browser preflight stages * test(browse): isolate Windows descendant console lifetime * test(browse): preserve native receipts and identify fixture lock holders * test(browse): prepare dependency resolution before native Mac worker startup * test(ci): include lock and close checks in native diagnostics * test(browse): preserve native owner probe stages and subprocess deadlines * fix(browse): classify Chromium profile-in-use exit precisely * test(browse): retain Mac qualification evidence through cleanup failures * test(browse): bound Mac fixture paths and retire its owned user domain * test(browse): accept vanished fixture entries without weakening cleanup * test(browse): identify probe-created macOS user domains safely * test(browse): observe Mac user domains without targeting them first * test(browse): use passive fresh-user ownership throughout Mac qualification * test(browse): distinguish profile and registered-home Keychain lookups * test(browse): qualify Dia under one registered account home * test(browse): identify Dia startup and owned process-group failures * test(browse): classify bounded Dia startup diagnostics without leaking output * fix(test): preserve native Mac sandboxing and reap owned browser children * fix(browse): preserve Chromium sandboxing for native profile imports * test(browse): inspect signed Mach-O architecture without launching Xcode tools * test(browse): sample pending Dia startup and reap on all cleanup paths * test(browse): compare protected Dia launches in fresh Bun and Node accounts * test(browse): inspect isolated Mac GUI readiness without browser access * v1.90.0.0 fix: bind cookie picker actions to their document * test: validate cookie guards and fit nested launch fixtures * ci: configure the bundled Chromium sandbox helper * fix(browse): classify Playwright authentication timeouts * test: retain bounded Windows lifecycle diagnostics * test(cso): reuse bounded NTFS precision candidates * test(review): handle explicit preservation choices safely * test(browse): remove owned fixture directories with explicit primitives * test(review): distinguish descriptive reuse from edit commitments * test: admit only the approved unscored cookie workflow refusal * test: keep the Office Hours judge mock export-complete * fix: keep dependency-free CI planners independent of the model SDK * test: observe the exact holder after a native fixture unlink failure * fix: start seeded PTY observations at owned readiness * test: acquire identity-bound Windows deletion admission before profile resets * test: preserve qualified Git index bits without authorizing mutations
This commit is contained in:
@@ -0,0 +1,96 @@
|
||||
import { expect, spyOn, test } from 'bun:test';
|
||||
import { Database } from 'bun:sqlite';
|
||||
import { mkdtempSync, mkdirSync, realpathSync, rmSync } from 'node:fs';
|
||||
import * as os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import { chromium, type Browser } from 'playwright';
|
||||
import { generatePickerCode, handleCookiePickerRoute, hasActivePicker } from '../src/cookie-picker-routes';
|
||||
|
||||
for (const sameOrigin of [false, true]) {
|
||||
test(`two real picker windows cannot reset the other ${sameOrigin ? 'same-origin tab' : 'same-host different-port origin'}`, async () => {
|
||||
const home = mkdtempSync(path.join(os.tmpdir(), 'picker-binding-'));
|
||||
const profile = path.join(home, '.config/chromium/Default');
|
||||
mkdirSync(profile, { recursive: true });
|
||||
expect(realpathSync(profile).startsWith(realpathSync(home) + path.sep)).toBe(true);
|
||||
const database = new Database(path.join(profile, 'Cookies'));
|
||||
database.run('CREATE TABLE cookies (host_key TEXT, name TEXT, value TEXT, encrypted_value BLOB, path TEXT, expires_utc INTEGER, is_secure INTEGER, is_httponly INTEGER, has_expires INTEGER, samesite INTEGER)');
|
||||
database.run('INSERT INTO cookies VALUES (?, ?, ?, ?, ?, 0, 0, 1, 0, 1)', ['127.0.0.1', 'fixture', 'synthetic', Buffer.alloc(0), '/']);
|
||||
database.close();
|
||||
const serveTarget = () => Bun.serve({ hostname: '127.0.0.1', port: 0, fetch(request) {
|
||||
const authenticated = (request.headers.get('cookie') ?? '').split(';').some(value => value.trim() === 'fixture=synthetic');
|
||||
return new Response(authenticated ? '<div id="fixture-identity">Synthetic account</div>' : '<div>Not signed in</div>', {
|
||||
headers: { 'Content-Type': 'text/html' }, status: authenticated ? 200 : 401,
|
||||
});
|
||||
} });
|
||||
const firstServer = serveTarget();
|
||||
const secondServer = sameOrigin ? firstServer : serveTarget();
|
||||
let browser: Browser | undefined;
|
||||
let picker: ReturnType<typeof Bun.serve> | undefined;
|
||||
let homeMock: ReturnType<typeof spyOn> | undefined;
|
||||
const selector = process.env.GSTACK_COOKIE_AUTH_SELECTOR;
|
||||
const identity = process.env.GSTACK_COOKIE_AUTH_EXPECTED_IDENTITY;
|
||||
try {
|
||||
browser = await chromium.launch({ headless: true });
|
||||
homeMock = spyOn(os, 'homedir').mockReturnValue(home);
|
||||
process.env.GSTACK_COOKIE_AUTH_SELECTOR = '#fixture-identity';
|
||||
process.env.GSTACK_COOKIE_AUTH_EXPECTED_IDENTITY = 'Synthetic account';
|
||||
const destination = await browser.newContext();
|
||||
destination.setDefaultTimeout(5_000);
|
||||
const targetA = await destination.newPage();
|
||||
const targetB = await destination.newPage();
|
||||
await targetA.goto(`http://127.0.0.1:${firstServer.port}/a`);
|
||||
await targetB.goto(`http://127.0.0.1:${secondServer.port}/b`);
|
||||
for (const target of [targetA, targetB]) {
|
||||
await target.evaluate(() => { localStorage.setItem('keep', 'preserved'); sessionStorage.setItem('keep', 'preserved'); });
|
||||
}
|
||||
const bm = { getActiveSession: () => ({ getPage: () => targetA }), trackCookieImportDomains() {} } as any;
|
||||
picker = Bun.serve({ hostname: '127.0.0.1', port: 0, fetch: request => handleCookiePickerRoute(new URL(request.url), request, bm) });
|
||||
const pickerOrigin = `http://127.0.0.1:${picker.port}`;
|
||||
const client = await browser.newContext();
|
||||
client.setDefaultTimeout(5_000);
|
||||
const windowA = await client.newPage();
|
||||
const windowB = await client.newPage();
|
||||
const importButton = /^(?:Import|Reimport) 127\.0\.0\.1$/;
|
||||
const errors: string[] = [];
|
||||
for (const window of [windowA, windowB]) window.on('pageerror', error => errors.push(error.message));
|
||||
const open = async (window: typeof windowA, target: typeof targetA) => {
|
||||
const code = generatePickerCode({ browser: 'Chromium', target: { page: target, url: target.url() } });
|
||||
await window.goto(pickerOrigin + '/cookie-picker?code=' + code);
|
||||
await window.getByRole('button', { name: importButton }).waitFor();
|
||||
await window.locator('#clear-storage').check();
|
||||
await window.locator('#verify-auth').check();
|
||||
};
|
||||
await open(windowA, targetA);
|
||||
await open(windowB, targetB);
|
||||
await windowA.getByRole('button', { name: importButton }).click();
|
||||
await windowA.getByRole('status').filter({ hasText: 'Reopen the picker from the intended page before continuing.' }).waitFor();
|
||||
for (const target of [targetA, targetB]) {
|
||||
expect(await target.evaluate(() => [localStorage.getItem('keep'), sessionStorage.getItem('keep')])).toEqual(['preserved', 'preserved']);
|
||||
}
|
||||
expect(await destination.cookies()).toEqual([]);
|
||||
expect(await targetA.locator('#fixture-identity').count()).toBe(0);
|
||||
expect(await targetB.locator('#fixture-identity').count()).toBe(0);
|
||||
await windowB.getByRole('button', { name: importButton }).click();
|
||||
await windowB.getByRole('status').filter({ hasText: 'Authentication verified on the captured target.' }).waitFor();
|
||||
expect(await targetB.evaluate(() => [localStorage.getItem('keep'), sessionStorage.getItem('keep')])).toEqual([null, null]);
|
||||
expect(await targetA.evaluate(() => [localStorage.getItem('keep'), sessionStorage.getItem('keep')])).toEqual([sameOrigin ? null : 'preserved', 'preserved']);
|
||||
expect(await targetB.locator('#fixture-identity').innerText()).toBe('Synthetic account');
|
||||
expect(await targetA.locator('#fixture-identity').count()).toBe(0);
|
||||
expect(errors).toEqual([]);
|
||||
} finally {
|
||||
homeMock?.mockRestore();
|
||||
if (selector === undefined) delete process.env.GSTACK_COOKIE_AUTH_SELECTOR;
|
||||
else process.env.GSTACK_COOKIE_AUTH_SELECTOR = selector;
|
||||
if (identity === undefined) delete process.env.GSTACK_COOKIE_AUTH_EXPECTED_IDENTITY;
|
||||
else process.env.GSTACK_COOKIE_AUTH_EXPECTED_IDENTITY = identity;
|
||||
await browser?.close();
|
||||
picker?.stop(true);
|
||||
firstServer.stop(true);
|
||||
if (!sameOrigin) secondServer.stop(true);
|
||||
const now = Date.now;
|
||||
Date.now = () => now() + 3_900_001;
|
||||
try { hasActivePicker(); } finally { Date.now = now; }
|
||||
rmSync(home, { recursive: true, force: true });
|
||||
}
|
||||
}, 40_000);
|
||||
}
|
||||
Reference in New Issue
Block a user